Description
A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.
Published: 2026-08-03
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Tenable Sensor Proxy permits a remote attacker to execute arbitrary code with elevated privileges by tricking an operator into connecting the sensor to a host under the attacker's control. Exploitation requires user interaction; once the sensor establishes the connection, the attacker gains code execution on the host powering the sensor. This flaw represents a high‑impact remote code execution (CWE‑94).

Affected Systems

Tenable, Inc.’s Sensor Proxy product is impacted. Any deployment running a version earlier than 1.4.2 remains vulnerable. Tenable has released 1.4.2 which addresses the issue; therefore only installations of Sensor Proxy that have not yet applied the 1.4.2 update or a later version remain at risk.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity. While the EPSS score is not available, the lack of a KEV listing suggests no publicly known exploits are documented yet, but the high score and user interaction requirement mean the threat exists if an operator is present. The attack vector is remote, relying on an operator inadvertently connecting the sensor to a malicious host, which grants the attacker capabilities such as system reconnaissance, data extraction, or further lateral movement. Administrators should treat this as a critical vulnerability requiring immediate action.

Generated by OpenCVE AI on August 4, 2026 at 09:36 UTC.

Remediation

Vendor Solution

Tenable has released Sensor Proxy 1.4.2 to address these issues. The installation files can only be obtained via the Tenable Downloads Portal ( https://www.tenable.com/downloads/sensor-proxy ).


OpenCVE Recommended Actions

  • Apply Tenable Sensor Proxy 1.4.2 or a later version from the Tenable Downloads Portal.
  • Reconfigure the sensor to accept connections only from trusted IP addresses and disable the ability for operators to connect to arbitrary hosts.
  • Monitor sensor logs for unexpected outbound connections and audit configurations regularly.

Generated by OpenCVE AI on August 4, 2026 at 09:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenable
Tenable sensor Proxy
Vendors & Products Tenable
Tenable sensor Proxy

Tue, 04 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.
Title Sensor Proxy Version 1.4.2 Fixes One Vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tenable Sensor Proxy
cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2026-08-05T03:56:44.048Z

Reserved: 2026-08-03T14:42:52.457Z

Link: CVE-2026-18667

cve-icon Vulnrichment

Updated: 2026-08-04T19:25:47.716Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-03T23:16:45.590

Modified: 2026-08-18T15:04:46.610

Link: CVE-2026-18667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:21:26Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')